Intel

AIKIDO-2025-10800

github.com/oauth2-proxy/oauth2-proxy/v7 is vulnerable to Server-side Request Forgery (SSRF)

Server-side Request Forgery (SSRF)CVE-2025-64484 Published Nov 12, 2025

85

High Risk

This Affects:

GOgithub.com/oauth2-proxy/oauth2-proxy/v7
7.0.0 - 7.12.0
Fixed in 7.13.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to server-side request forgery (SSRF) via header smuggling. Authenticated users can inject underscore-prefixed X-Forwarded_* headers (e.g., X_Forwarded-For) which bypass the normal stripping logic, allowing privilege escalation or impersonation of upstream clients.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/oauth2-proxy/oauth2-proxy/v7 is vulnerable to Server-side Request Forgery (SSRF) in versions 7.0.0 - 7.12.0.

How to fix this

Upgrade the github.com/oauth2-proxy/oauth2-proxy/v7 library to a patch version.